Description
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Remediation
References
Related Vulnerabilities
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8167)
WordPress Plugin Top 10-Popular posts for WordPress Multiple Vulnerabilities (3.2.4)
WordPress Plugin Bitcoin Faucet Cross-Site Scripting (1.0.12)
phpMyAdmin Other Vulnerability (CVE-2004-1147)
MediaWiki Improper Access Control Vulnerability (CVE-2012-4379)